Security Analyst, CSOC

Lever, Inc.

India

Remote

INR 900,000 - 1,500,000

Full time

32 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Medical, dental, and vision insurance
Provident Fund
Remote work within India
AI and automation exposure

Job summary

Lever, Inc. in India is seeking a Security Analyst for a 24/7 CSOC role focused on protecting systems, networks, and data. You will analyze security events, investigate intrusions, and support rapid containment and remediation across SIEM, EDR, firewalls, and IDS/IPS.

The role emphasizes hands-on monitoring, incident response, threat analysis, and forensics, with collaboration across security, engineering, and application teams. AI tools and automation will be leveraged to improve efficiency.

Qualifications

  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or related discipline, or 2–5 years of SOC/IR/forensics experience.
  • At least 2 years of SOC experience, including internship experience.
  • Hands-on with Splunk SIEM and security log analysis across technologies (firewalls, proxies, EDR).
  • Experience handling cyber incidents, L1 analysis, false positives, and event correlation.
  • Solid understanding of networks, TCP/IP, OSI layers, architectures, and IDS/IPS.
  • Knowledge of web app architecture, AD, HTTP/SMTP/DNS.
  • Understanding of malware types and techniques.
  • Strong analytical, organizational, documentation, and time-management skills.
  • Clear communication across teams.
  • Ability to work in fast-paced environments and prioritize.
  • Experience partnering with network/engineering teams is a plus.
  • Security certifications such as CompTIA Security+ are preferred.
  • Familiarity with AI productivity tools like ChatGPT or Copilot is a plus.

Responsibilities

  • Monitor and analyze network traffic, security events, alerts, and threat indicators; recommend remediation and escalation.
  • Investigate incidents by correlating sources to identify affected systems and data.
  • Analyze logs from SIEM, EDR, firewalls, proxies, NIDS/HIDS to identify malicious activity and response paths.
  • Independently identify, classify, contain, investigate, document, and eradicate threats per procedures.
  • Perform L1 security event analysis; identify false positives; escalate high-risk incidents.
  • Assess incident impact and determine remediation actions to restore secure operations.
  • Follow procedures for detecting, documenting, reporting, and escalating incidents and threat intel.
  • Collaborate with engineering, network, app, and security teams for effective resolutions.
  • Apply AI tools and automation to streamline analysis and improve response.

Skills

Splunk SIEM
Incident response
Threat analysis
Log analysis
Networking concepts
TCP/IP knowledge
Team collaboration
Certifications
AI/automation familiarity

Education

Bachelor's degree in CS/IS/Cybersecurity
2–5 years SOC experience

Tools

Firewalls
Proxies
EDR platforms

Job description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security Analyst, CSOC based in India.

This role is part of a 24/7 Cyber Security Operations Center, focused on protecting systems, networks, and data from evolving threats.

You will analyze security events, investigate potential intrusions, and support rapid containment and remediation.

The position combines hands-on security monitoring with incident response, threat analysis, and forensic investigation.

You will work across logs and telemetry from SIEM, EDR, firewalls, IDS/IPS, and other security technologies to connect events and identify threats.

The role offers close collaboration with security, engineering, network, and application teams in a fast-paced environment.

You will also have opportunities to use AI and automation to reduce manual work and improve security decision-making.

This is an opportunity to strengthen enterprise defenses while developing your expertise across modern cybersecurity operations.

Accountabilities
  • Monitor and analyze network traffic, security events, alerts, and threat indicators, recommending appropriate remediation and escalation actions.

  • Investigate security incidents and intrusion attempts by correlating information from multiple sources to determine affected systems, applications, or data.

  • Analyze logs from SIEM, EDR, firewalls, proxies, NIDS, HIDS, and host systems to identify malicious activity and establish appropriate response paths.

  • Independently identify, classify, contain, investigate, document, and eradicate security threats in accordance with established procedures.

  • Perform L1 security event and incident analysis, identify false positives, correlate related events, and **escalate** confirmed or high-risk incidents appropriately.

  • Assess the potential impact of incidents and determine the remediation actions required to reduce risk and restore secure operations.

  • Follow established procedures for detecting, documenting, reporting, and escalating security incidents and threat intelligence.

  • Collaborate with engineering, network, application, and security teams to support effective incident resolution and strengthen defensive capabilities.

  • Apply practical AI tools and automation where appropriate to streamline analysis, reduce repetitive work, and improve response efficiency.

Requirements
  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related discipline, or 2–5 years of relevant experience in SOC operations, incident response, or cyber forensics.

  • At least 2 years of SOC experience, including relevant internship experience.

  • Hands-on experience with Splunk SIEM and security log analysis across technologies such as firewalls, proxies, and EDR platforms.

  • Practical experience handling cyber incidents, performing L1 analysis, identifying false positives, and correlating security events.

  • Solid understanding of network architecture, TCP/IP, OSI layers, network and systems architecture, and intrusion detection technologies.

  • Knowledge of web application architecture, Active Directory, and application-layer protocols including HTTP, SMTP, and DNS.

  • Understanding of common malware types and attack techniques, including rootkits, trojans, adware, exploits, and fileless malware.

  • Strong analytical, organizational, documentation, prioritization, and time-management skills.

  • Clear written and verbal communication skills, with the ability to collaborate effectively across technical and organizational teams.

  • Ability to work in a fast-paced environment, manage competing priorities, navigate ambiguity, and make sound decisions with incomplete information.

  • Experience partnering with network, engineering, or application teams is an advantage.

  • Security certifications such as CompTIA Security+ or equivalent are preferred.

  • Familiarity with AI productivity tools such as ChatGPT, Copilot, or similar technologies is a plus.

Benefits
  • Competitive compensation and benefits package.

  • Medical, dental, and vision insurance.

  • Provident Fund.

  • Life and accident insurance.

  • Internet, fuel, meal, and telephone allowances.

  • Remote work arrangement within India.

  • Opportunities to work with modern cybersecurity, AI, and automation technologies.

  • A collaborative environment with opportunities to work across security, engineering, network, and application functions.

  • Benefits and eligibility may vary according to location and employment status.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Chief Analyst, Cyber Security Operations
Chief Analyst, Cyber Security Operations

SES S.A Brazil • Chennai District

On-site
INR 3,500,000 - 6,000,000
Associate Analyst - Cyber Defence Center
Associate Analyst - Cyber Defence Center

Fresenius Medical Care • Bengaluru

On-site
INR 500,000 - 900,000
Security Analyst
Security Analyst

Litmos • India

On-site
INR 2,400,000 - 3,200,000
Lead Engineer, Information Security
Lead Engineer, Information Security

Lever, Inc. • India

Remote
INR 1,500,000 - 2,200,000
Fully remote within India
Senior technical ownership
Exposure to enterprise SIEM/EDR/cloud
+3
SOC Analyst – Level 1 (L1)
SOC Analyst – Level 1 (L1)

Techsec Digital Global Private Limited • Mumbai Suburban

On-site
INR 350,000 - 650,000
Security Analyst
Security Analyst

SHI • Hyderabad

Remote
INR 600,000 - 1,200,000
Security Operations Analyst
Security Operations Analyst

Comscore Technologies • Pune District

On-site
INR 1,200,000 - 1,800,000
SISA Information Security - Security Operations Center Manager - SIEM/SOAR
SISA Information Security - Security Operations Center Manager - SIEM/SOAR

SISA • Bengaluru

On-site
INR 3,000,000 - 5,200,000
CYBER security Analyst
CYBER security Analyst

Cortex Consultants LLC • Chennai

On-site
INR 1,200,000 - 1,800,000
SOC L1
SOC L1

Sanganan It Solutions • Dadri

On-site
INR 600,000 - 900,000